Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(deps): update dependency certifi to v2023 [security] #5357

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Oct 24, 2023

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
certifi ==2018.1.18 -> ==2023.7.22 age adoption passing confidence

GitHub Vulnerability Alerts

CVE-2022-23491

Certifi 2022.12.07 removes root certificates from "TrustCor" from the root store. These are in the process of being removed from Mozilla's trust store.

TrustCor's root certificates are being removed pursuant to an investigation prompted by media reporting that TrustCor's ownership also operated a business that produced spyware. Conclusions of Mozilla's investigation can be found here.

CVE-2023-37920

Certifi 2023.07.22 removes root certificates from "e-Tugra" from the root store. These are in the process of being removed from Mozilla's trust store.

e-Tugra's root certificates are being removed pursuant to an investigation prompted by reporting of security issues in their systems. Conclusions of Mozilla's investigation can be found here.


Release Notes

certifi/python-certifi (certifi)

v2023.7.22

Compare Source

v2023.5.7

Compare Source

v2022.12.7

Compare Source

v2022.9.24

Compare Source

v2022.9.14

Compare Source

v2022.6.15.2

Compare Source

v2022.6.15.1

Compare Source

v2022.6.15

Compare Source

v2022.5.18.1

Compare Source

v2022.5.18

Compare Source

v2021.10.8

Compare Source

v2021.5.30

Compare Source

v2020.12.5

Compare Source

v2020.11.8

Compare Source

v2020.6.20

Compare Source

v2020.4.5.2

Compare Source

v2020.4.5.1

Compare Source

v2020.4.5

Compare Source

v2019.11.28

Compare Source

v2019.9.11

Compare Source

v2019.6.16

Compare Source

v2019.3.9

Compare Source

v2018.11.29

Compare Source

v2018.10.15

Compare Source

v2018.8.24

Compare Source

v2018.8.13

Compare Source

v2018.4.16

Compare Source


Configuration

📅 Schedule: Branch creation - "" in timezone US/Eastern, Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot force-pushed the renovate/pypi-certifi-vulnerability branch 2 times, most recently from bea1926 to dd4ac04 Compare February 6, 2024 16:16
@renovate renovate bot changed the title chore(deps): update dependency certifi to v2023 [security] Update dependency certifi to v2023 [SECURITY] Feb 6, 2024
@renovate renovate bot force-pushed the renovate/pypi-certifi-vulnerability branch 3 times, most recently from 9c3051a to bf44643 Compare March 6, 2024 13:53
@renovate renovate bot force-pushed the renovate/pypi-certifi-vulnerability branch 2 times, most recently from a879530 to 7c8cd88 Compare March 26, 2024 12:43
@renovate renovate bot changed the title Update dependency certifi to v2023 [SECURITY] chore(deps): update dependency certifi to v2023 [security] Mar 26, 2024
@renovate renovate bot force-pushed the renovate/pypi-certifi-vulnerability branch from 7c8cd88 to 06bd110 Compare March 26, 2024 14:37
@renovate renovate bot force-pushed the renovate/pypi-certifi-vulnerability branch from 06bd110 to b16c822 Compare April 2, 2024 15:06
@renovate renovate bot force-pushed the renovate/pypi-certifi-vulnerability branch 2 times, most recently from 8c54a56 to a3ed463 Compare April 17, 2024 12:03
@renovate renovate bot force-pushed the renovate/pypi-certifi-vulnerability branch 4 times, most recently from d9a7162 to d05302c Compare April 25, 2024 18:07
@renovate renovate bot force-pushed the renovate/pypi-certifi-vulnerability branch from d05302c to 703bb11 Compare May 3, 2024 15:46
@renovate renovate bot force-pushed the renovate/pypi-certifi-vulnerability branch 2 times, most recently from 7aee1b4 to 9b5c63a Compare May 20, 2024 19:53
@renovate renovate bot force-pushed the renovate/pypi-certifi-vulnerability branch from 9b5c63a to 4c2e443 Compare May 28, 2024 20:06
@renovate renovate bot force-pushed the renovate/pypi-certifi-vulnerability branch from 4c2e443 to ca83ccb Compare June 17, 2024 14:54
@renovate renovate bot force-pushed the renovate/pypi-certifi-vulnerability branch from ca83ccb to 95b83bb Compare June 17, 2024 15:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants